This policy covers two different things, and it is worth keeping them apart: information about you as a visitor to this website, and information Keelson handles on behalf of a client while running their site or platform. The rules are different for each.
1. Who is responsible
Keelson Systems LLC, a South Carolina limited liability company, Columbia, South Carolina. Privacy questions go to hello@keelsonsystems.org.
2. This website collects essentially nothing
This site is static. It has no analytics, no advertising, no tracking pixels, no third-party scripts, and no cookies. There is no contact form — the contact link opens your own email client, so nothing is submitted to us through the page.
Two things do happen automatically, because they are how the web works:
Server logs. The hosting infrastructure records ordinary request information — IP address, timestamp, requested URL, response status, browser user-agent. This exists to serve pages, catch errors, and identify abuse. It is retained for up to 30 days and then discarded.
Google Fonts. The page loads typefaces from fonts.googleapis.com and
fonts.gstatic.com. Your browser makes a request to Google to fetch them, which
discloses your IP address to Google. No font request carries a cookie or an identifier
we set. Google's handling is governed by its own privacy policy.
If you email us, we have your email — obviously — and we keep that correspondence as long as it is useful for the business relationship.
Keelson's own billing. When you become a client, Keelson holds the information it needs to invoice you: business name, billing contact, billing address, and invoice history. Invoices are paid through Stripe, a PCI-compliant payment processor; Keelson does not store, process, or transmit card numbers. Stripe's handling of your payment details is governed by its own privacy policy.
3. Information Keelson handles for clients
When Keelson hosts a client's website or provides platform access, we process data belonging to that client and to their members or customers — names, contact details, scheduling records, and membership records. In that role Keelson is a processor acting on the client's instructions, and the client decides what is collected and why.
For that data, Keelson:
- processes it only to provide the services the client has contracted for;
- does not sell it, rent it, or trade it, under any circumstances;
- does not use it to train models or to build a marketing profile;
- discloses it only to the subprocessors listed below, or where the law requires;
- returns it to the client in a standard machine-readable export on request or on termination, and deletes it on the client's instruction.
Payments are not ours to hold. Client payment processing runs against the client's own Stripe account. Card data never touches Keelson's systems, and member payments go to the client's processor and the client's bank — never through Keelson.
If you are a member or customer of a Keelson client and want your data corrected or deleted, contact that business directly. They control it. We will act on their instruction promptly.
4. Subprocessors
Keelson uses a small number of vendors to deliver services. Each is bound by its own data-protection commitments.
| Vendor | Purpose | Scope |
|---|---|---|
| Google Cloud Platform | Hosting, compute, databases, secret storage (region us-east1) |
Client site and platform data |
| Cloudflare | DNS and edge routing | Request metadata |
| Google Workspace | Business email | Correspondence |
| Stripe | Payment processing | Client-owned accounts; Keelson does not hold card data |
| Twilio | SMS notifications, where a client has enabled them | Recipient phone numbers |
| Resend | Transactional email from client applications | Recipient email addresses |
| Supabase | Authentication, where already in place for a client | Account credentials |
Each client is provisioned in its own isolated Google Cloud project. No database instance is shared between clients.
Adding a subprocessor that handles client data means updating this table and notifying affected clients.
5. How long data is kept
Website server logs: up to 30 days. Business correspondence: for the duration of the relationship and a reasonable period after, for tax and legal records. Client data: for as long as the client's agreement runs, then exported and deleted on the client's instruction. Backups roll off on their own schedule and are not retained indefinitely.
6. Security
Keelson maintains administrative, technical, and physical safeguards appropriate to the data it processes. In practice that means secrets held in a managed secret store rather than in code or environment files, one isolated cloud project per client, encryption in transit, least-privilege access, and a three-stage security gate on every deployment: verified-secret scanning before the build, container vulnerability scanning after it, and a passive vulnerability scan against the running site before it takes traffic.
No system is perfectly secure, and anyone who tells you otherwise is selling something.
If Keelson becomes aware of a security incident affecting client data, we notify the affected client without undue delay and in any event within seventy-two hours, with reasonable detail about what happened, what data was involved, and what we are doing about it.
To report a vulnerability, email security@keelsonsystems.org. Reports made in good faith are welcome and will not be pursued.
7. Your rights
Depending on where you live, you may have the right to ask what personal data is held about you, to have it corrected, to have it deleted, to receive a copy in a portable format, or to object to certain processing.
For data this website holds about you — which is very little — email hello@keelsonsystems.org. For data held on behalf of a client, contact that business; they control it and we act on their instruction.
Keelson does not sell personal information and does not share it for cross-context behavioral advertising.
8. Children
Keelson's services are sold to businesses and are not directed at children under 13. Where a client's own platform records information about a minor — a youth member at a gym, for example — that client is responsible for obtaining any required parental consent, and Keelson processes it only on their instruction.
9. International visitors
Keelson operates in the United States and its infrastructure is hosted in the United States. If you visit from elsewhere, your information is processed here.
10. Changes
Material changes are posted here with a new "last updated" date. Where a change affects a client engagement, affected clients are notified directly.
11. Contact
Keelson Systems LLC Columbia, South Carolina hello@keelsonsystems.org · security@keelsonsystems.org